Using Multi-factor authentication (MFA)

  • Release version: Washingtondc
  • Updated February 1, 2024
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using Multi-factor Authentication (MFA)

    Multi-factor authentication (MFA) enhances security by requiring a second form of verification when accessing your ServiceNow instance. Supported authenticator applications include Google Authenticator, Microsoft Authenticator, LastPass Authenticator, Authy, FreeOTP, Duo, and Okta Verify. Other applications may work but are not officially tested.

    Show full answer Show less

    Key Features

    • Login with MFA: After entering your username and password, you will be prompted for a second authentication method.
    • Authenticator App Validation: Enter the code from your authenticator app to log in.
    • Biometric Authenticators: If allowed, configure fingerprint or facial recognition as a second authentication method.
    • Hardware Key Authenticators: Register physical security devices for authentication.
    • SMS OTP: Receive a six-digit code via SMS to verify your identity, valid for 5 minutes.
    • Email OTP: Receive a six-digit code via email to verify your identity, also valid for 5 minutes.

    Key Outcomes

    Implementing MFA improves the security of your ServiceNow instance by adding multiple layers of verification. Users will experience a streamlined setup process for authenticators and can choose from several methods of verification, ensuring that access to sensitive data is well-protected.

    Learn how to use multi-factor authentication tools to securely access your instance.

    Login with MFA

    ServiceNow requires authenticator applications that support Time-based One-time Passwords (TOTP). ServiceNow tests MFA with the following authenticators:
    • Google Authenticator
    • Microsoft Authenticator
    • LastPass Authenticator
    • Authy
    • FreeOTP
    • Duo
    • Okta Verify
    Note:
    Other authenticators not listed might also be compatible, but are not tested by ServiceNow.
    Note:
    For information related to browser specific behavior change, see this KB article.

    If your administrator has enabled multi-factor authentication (MFA) on your instance, you are prompted for a second authentication after entering your user name and password. For details on the MFA login process, see Log in with multi-factor authentication

    If you haven't configured a second form of authentication, you will see a configuration page after logging in to guide you through the process of setting up an authentication app. For details on this setup, see Setup multi-factor authentication upon initial login.

    Validation with authenticator app


    Authenticator

    Enter the code displayed on your authenticator app to login.

    Register an authentication device

    After you've configured an authentication app, you can register other methods for authentication.
    Biometric authenticators
    You can use biometric authenticators like fingerprint or facial recognition as your second MFA authentication. If your administrator allows this option, you can configure biometric authenticators using the steps in Register a biometric authenticator.
    Hardware key authenticators
    Hardware keys are physical security devices you can use for authentication. You can register a hardware device for use with your instance using the steps in Register a hardware security key.

    Biometrics icon

    Hardware key icon

    Validation with Biometric or Hardware Key


    MFA - Biometric or Hardware
    Use the Biometric or Security Key to login.

    Register a phone number for OTP

    SMS
    Admin configures ServiceNow instance to require users who attempt to login the instance using SMS based OTP.

    When users attempt to login to ServiceNow, SMS OTP is sent to the mobile number associated with the sys_user record. Users can enter the six-digit verification code that it sent to the mobile device and verify their identity.


    SMS

    Validation with SMS


    MFA-SMS
    Enter the 6-digit code sent to the mobile number to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code.

    Register an Email address for OTP

    Email address
    Admin configures ServiceNow instance to require users who attempt to login the instance using Email based OTP.

    When users attempt to login to ServiceNow, Email OTP is sent to the email address associated to the user. User's can enter the six-digit verification code that it sent to the mobile device and verify their identity.


    Email

    Validation with Email


    MFA-Email
    Enter the 6-digit code sent to the email address to login. The code sent is valid for the next 5 minutes. You can use resend code to again send the code.